/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Thanks for the heads up.  I was for some reason thinking SQUID handled the packet
redirection without needing IPCHAINs.  But, with this configuration it will run
transparently (ie you don't need to do anything to your clients browsers to make
them work with the proxy server.

Dan

Chris Garrigues wrote:

> > From:  Jake Colman <[EMAIL PROTECTED]>
> > Date:  29 Dec 1999 12:29:07 -0500
> >
> > /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
> >
> >
> > >>>>> "DF" == Daniell Freed <[EMAIL PROTECTED]> writes:
> >
> >     DF> Now, I'm no expert at Squid (and I imagine there is a Squid mailing
> >     DF> list) but if you set up Squid on the firewall, it can act as a
> >     DF> transperant proxy server, meaning that it will sit on your firewall
> >     DF> and all web traffic (as well as some other traffic depending on you
> > r
> >     DF> configuration) will be proxied by Squid.  This doesn't require any
> >     DF> changes to your client machine's browsers (I don't think).
> >
> >     DF> I don't think you need to bother writing any special IPChains rules
> >     DF> to do this.
> >
> > But it can only be a transparent proxy server if I configure netscape to us
> > e
> > it as a proxy server (then I guess it's not totally transparent, is it?).
> > You must manually configure each system's browser to send url requests to t
> > he
> > proxy server on the required port.  Now I _could_ use ipchains to reject an
> > y
> > outgoing packets on port 80 and thereby ensure that noone bypasses the
> > proxy.  Instead, I'd like to use ipchains to transparently redirect the
> > outgoing packet to the squid port and let squid handle it.
>
> I've got this line in my ipchains.save:
>
> -A input   -s 10.1.2.0/8 -d default/0 80 -p tcp -j REDIRECT 3128
>
> It says "if the source address is on my network and the destination address is
> port 80, redirect it to port 3128" (which is where squid runs).
>
> I believe this is documented in multiple places and I suspect that the hint
> that's inserted at the top of every message to this list would have also found
> the answer.
>
> Chris
>
> --
> Chris Garrigues                 virCIO
> http://www.DeepEddy.Com/~cwg/  http://www.virCIO.Com
> +1 512 432 4046                 +1 512 374 0500
>                                 4314 Avenue C
> O-                              Austin, TX  78751-3709
>
>
>   My email address is an experiment in SPAM elimination.  For an
>   explanation of what we're doing, see http://www.DeepEddy.Com/tms.html
>
>     Nobody ever got fired for buying Microsoft,
>       but they could get fired for relying on Microsoft.
>
>   ------------------------------------------------------------------------
>    Part 1.2Type: application/pgp-signature

--
Daniell Freed
Computer Services
Dewitt, Ross, & Stevens

He who fights with monsters might take care
lest he thereby become a monster.
And if you gaze for long into an abyss,
the abyss gazes also into you.

Beyond Good and Evil
Friedrich Wilhelm Nietzche

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to